Interesting. I'm not sure if the public comment period is over (The original proposal is dated August, 2023), but this stands out to me from their paper: We propose to focus the scope of our program on intentional radiators that generate and emit RF energy by radiation or induction.31 Such devices – if exploited by a vulnerability – could be manipulated to generate and emit RF energy to cause harmful interference. Wh…
Seems to me that this would wholesale rule out projects like the ESP32 open WiFi driver. Or rather, in order to comply, espressif would have to retool their chips to make "unauthorized" aceess to the raw radio hardware impossible. Sort of how cellular modems are now.
Seems reasonable from the FCC's perspective, but I'm not sure how I'd feel about it.
I'm interested in the actual details here -- 1) What are the requirements for the mark? E.g. no passwords stored in plaintext on servers, no blank/default passwords on devices for SSH or anything else, a process for security updates, etc.? 2) Who is inspecting the code, both server-side and device-side? 3) What are the processes for inspecting the code? How do we know it's actually being done and not just being rubbe…
Good questions. As I understand, they spent months to decide who will be responsible and who will pay (and how much). Announce happen after budget passed Parliament, so now could make manning table and hire people for next steps.
Some questions already answered in article - from gov't responsible NIST and FCC and from industry agreed to participate deputies from large companies, so now they will gather meetings and will create some documents.
So now, any interested subject (any human or entity, even "group of hackers") could ask to responsible. Or could talk with deputies, as their contacts should appear soon.
Interesting. I'm not sure if the public comment period is over (The original proposal is dated August, 2023), but this stands out to me from their paper: We propose to focus the scope of our program on intentional radiators that generate and emit RF energy by radiation or induction.31 Such devices – if exploited by a vulnerability – could be manipulated to generate and emit RF energy to cause harmful interference. Wh…
Some questions already answered in article - from gov't responsible NIST and FCC and from industry agreed to participate deputies from large companies, so now they will gather meetings and will create some documents.
So now, any interested subject (any human or entity, even "group of hackers") could ask to responsible. Or could talk with deputies, as their contacts should appear soon.
This is all well and good. You can have thousands of "mark of approvals", but is the most important item needed required ? User upgradability if the Company Folds or Sunsets the product. When that happens, the user will need to buy a new device or live with comprised devices. Most will live with the comprised device. So, IMO, the product should be fully open source and easily upgraded in order to get the Cyber Trust…
> User upgradability if the Company Folds or Sunsets the product.
This isn't something which a company can meaningfully guarantee to consumers. Even if it's technically possible for users to install their own software on a device - for that matter, even if the company goes out of their way to support it by releasing documentation and source code - there simply isn't interest from developers to build and maintain custom software for those devices. And the same goes for devices which depend on online services - those services cost money to run, and the number of users capable and willing to run their own is miniscule.
Interesting. I'm not sure if the public comment period is over (The original proposal is dated August, 2023), but this stands out to me from their paper: We propose to focus the scope of our program on intentional radiators that generate and emit RF energy by radiation or induction.31 Such devices – if exploited by a vulnerability – could be manipulated to generate and emit RF energy to cause harmful interference. Wh…
You might be getting a bit too far ahead of where the industry is at with some of those wishlist items. NIST's requirements are things that are best practices that everyone agrees with, like: * data stored/transmitted is secured by some kind of means * the device supports software updates * the device requires users to authenticate * the device has documentation * you can report security vulnerabilities to the develo…
> But for now, you can presume the Netflix button on your TV remote can't be configured to point to an alternative API if Netflix goes away. :)
At least for Android TV devices, Button Mapper works for some.
The vendor is supposed to check I think. Not that that makes sense in a comingling inventory world.
I'm sure Amazon - whose store is mostly generic Chinese schlock nowadays - will check. Not that it matters, posters on this very site who claim to care will continue buying stuff off AliExpress, proud they got it for pennies on the dollar. Look ma, a mini PC for $22! And they didn't even charge for the preinstalled malware! Has anyone ever considered this junk is sold at a loss as a price of doing business, to expand…
Looks like you just have not deal with bad traders on platforms. I once found on local aggregator product too cheap to be good (unfortunately at that moment only two stores sell these product).
I stored their number in my notebook and going to my shopping, calling them from bus stop, and they answered me some nonsense.
I made my shopping, and some walk, then opened platform and these shops already disappear. Less than hour.
In other case I managed to make order and paid from card, and also shop disappeared. - In a week I received SMS from bank "your payment returned to your account".
I wonder how much this is going to add to the cost/effort of creating a new IOT product for startups/small businesses?
Based on the sorts of recommendations in [1], probably not to any meaningful degree, if at all. Much of what it's asking for is table-stakes functionality, along the lines of "have a factory reset feature", "use encryption when transmitting data", or "have a product support page" - things that any responsible developer should have been doing already.
Cool, I'd rather have a stamp that indicates a company will support their product for X number of years, and if they don't, they will release the software as OSS so you can maintain yourself. I have an extremely expensive scale that came with wifi support and an app, only bought it 3 years ago, half the features already don't work because they nuked the app and stopped supporting the scale. did I need a smart scale?…
Yeah, nowadays i try to buy many things that are "not smart" in order to avoid what you experienced with the smart scale. That being said, i wonder if what you're asking for is more on the warranty side, rather than security/promise side? To clarify, i am 100% in agreement with you that after a company stops supporting a product, they should open source it (which could create a secondary ecosystem of techs who offer services to support said open source software if a person is not inclined to manage the OSS themselves, etc.)...However, technically wouldn't a company's "promise" to support software be more like a warranty? And in that case, whatever gov. agency who oversees warranties would need to nudge business to comply...nevertheless both this cybermark, a warranty on software lifecycle, and other things are the LEAST that shoild exist nowadays.
I wonder how much this is going to add to the cost/effort of creating a new IOT product for startups/small businesses?
I honestly don't know...but isn't this sort of like when toasters first came out? I don't know for sure, but i guess toasters maybe didn't have the UL symbol...and probably some accidents happened, maybe house fires and such? Fast forward to nowadays and toasters tend to be pretty safe - well, if used properly and purchased from a reputable manufacturer who has been tested via entities like UL, etc....So yeah, maybe a little extra cost...but wouldn't we want at least some modicum of a signal of quality assurances for IoT devices - like we have for things like toasters?
I'm sure Amazon - whose store is mostly generic Chinese schlock nowadays - will check. Not that it matters, posters on this very site who claim to care will continue buying stuff off AliExpress, proud they got it for pennies on the dollar. Look ma, a mini PC for $22! And they didn't even charge for the preinstalled malware! Has anyone ever considered this junk is sold at a loss as a price of doing business, to expand…
Looks like you just have not deal with bad traders on platforms. I once found on local aggregator product too cheap to be good (unfortunately at that moment only two stores sell these product). I stored their number in my notebook and going to my shopping, calling them from bus stop, and they answered me some nonsense. I made my shopping, and some walk, then opened platform and these shops already disappear. Less tha…
Sorry my post was sarcasm. If English is a second language I can see where that could be lost in translation. I don't expect any of these vendors, especially Amazon 3rd party, to check.